ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A U.S. retailer uses an IaaS provider that may mirror customer data from its Frankfurt region to servers in South Africa for disaster-recovery purposes. Because the data includes EU residents' personally identifiable information, the retailer is concerned about violating GDPR restrictions on international transfers. Which contract provision best reduces this legal risk?
A right-to-audit clause allowing the retailer to inspect the provider's data centers
A service-level agreement guaranteeing 99.999 percent availability with financial penalties
A contractual reference to the U.S. CLOUD Act to handle government disclosure requests
Inclusion of the European Commission's Standard Contractual Clauses governing transfers of personal data outside the EEA
Under the GDPR, personal data may leave the European Economic Area only if adequate safeguards exist. The European Commission's Standard Contractual Clauses (SCCs) are an approved safeguard that contractually obligates both the data exporter and the data importer to provide GDPR-equivalent protections when data is sent to a third country such as South Africa, which does not currently have an EU adequacy decision. Adding SCCs to the outsourcing agreement therefore directly addresses the cross-border transfer risk. A right-to-audit clause improves oversight but does not by itself satisfy Article 46 requirements. A 99.999 percent availability commitment concerns service uptime, not data-transfer legality. Referencing the U.S. CLOUD Act relates to government access requests and does not create a lawful basis for exporting EU personal data.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Standard Contractual Clauses (SCCs) under GDPR?
Open an interactive chat with Bash
What is GDPR Article 46, and how does it relate to international data transfers?
Open an interactive chat with Bash
Why doesn't a right-to-audit clause satisfy GDPR requirements for cross-border data transfers?
Open an interactive chat with Bash
What are Standard Contractual Clauses (SCCs)?
Open an interactive chat with Bash
Why is the European Economic Area (EEA) important in GDPR compliance?
Open an interactive chat with Bash
What is an adequacy decision under GDPR?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .